RELEASE NOTES & SECURITY REPORTS

Free scanners, vulnerability reports, and platform-specific guidance. No fluff.

Proof Over Alerts: How to Judge a Tool That Claims to Find Real Exploitable Bugs, Not Noisy Alerts
2026.07.26 · 8 MIN READ · An alert is a claim; proof is a reproducible demonstration. Why alert volume is the wrong metric and how gapbench's clean controls make …
SCANNER
Vibe Coding Security Monthly — July 2026: Slopsquatting Gets a Name, the Injective SDK Falls, and the Defense Stack Ships — rust-review, AI SAST, Managed DevSecOps
2026.07.13 · 9 MIN READ · A confirmed npm supply chain compromise in @injectivelabs/sdk-ts (~50,000 weekly downloads) hooks wallet key-derivation and exfiltrates …
SCANNER
Vibe Coding Security Weekly — June 8, 2026: The Agent Becomes the Weapon and the Target — Sophos Catches Claude+Cursor Building Malware, Miasma Plants .cursor/rules in Microsoft Repos, RedHat npm Falls
2026.06.08 · 9 MIN READ · Sophos X-Ops documents a threat actor using Cursor and Claude Opus 4.5 to build an 80-module EDR-evasion framework — the agent as weapon. …
SCANNER
Lovable Security Report June 2026: The Agent-Integration Layer Goes Operational
2026.06.08 · 7 MIN READ · The attack class May named went live in June. Sophos caught a threat actor using Cursor and Claude Opus 4.5 to build an 80-module …
SCANNER
Vibe Coding Security Weekly — June 1, 2026: '62%' Chases '45%', Moltbook Becomes the Reference Breach, Thoughtworks Names the Root Cause, GitHub Weighs PR Gates
2026.06.01 · 8 MIN READ · OX Security puts the number at 62%, one week after Veracode's 45% became canon — and the field quietly admits the number won't settle. The …
SCANNER
Vibe Coding Security Weekly — May 25, 2026: Apple Pulls 'Anything', Cursor Ships Composer 2, OpenAI Eyes $3B Windsurf Deal, Veracode 45% Becomes Canon
2026.05.25 · 8 MIN READ · Apple removes the 'Anything' vibe-coding app under Guideline 2.5.2 — the app reappears on Google Play in 30 seconds. Cursor ships its own …
SCANNER
Vibe Coding Security Weekly — May 18, 2026: 1,764-App Audit Confirms RedAccess, Cursor Ships Bugbot, Mini Shai-Hulud Hits 169 npm Packages
2026.05.18 · 8 MIN READ · B1KEY's 1,764-app audit independently confirms the RedAccess shape (7% wide-open Supabase, IDOR-by-URL-increment). Cursor announces Bugbot. …
SCANNER
2026 AI Coding Security Report: The Data Behind the Vibe-Coding Breach Wave
2026.05.13 · 13 MIN READ · May 2026 update built on a 1,812-event firehose corpus across 7.5 days. 380,000 vibe-coded assets indexed, ~5,000 leaking sensitive data. …
SCANNER
Vibe Coding Security Weekly — May 11, 2026: RedAccess Finds 380K Exposed Apps, TrustFall Hits AI Agents, Replit Ships Security Agent
2026.05.11 · 7 MIN READ · RedAccess scanned 380,000 vibe-coded apps and found ~5,000 leaking corporate data. WIRED and Axios verified. Plus TrustFall (AI coding …
SCANNER
Lovable Security Report May 2026: The Defender Stack Reorganizes Around Vibe Coding
2026.05.11 · 8 MIN READ · May 2026 was the month vibe-coding security defenders started shipping. Replit launched Security Agent + Workspace Security Center 2.0. …
SCANNER
Vibe Coding Security Weekly — May 5, 2026: Replit vs Apple Goes Legal, Mythos Finds 271 Firefox Bugs, Gemini CLI CVSS-10 RCE
2026.05.05 · 6 MIN READ · A week of escalation: Replit's CEO calls Apple's App Store block a 'total lie' and threatens court, Anthropic's Mythos preview helps Mozilla …
SCANNER
VibeEval vs Competitors: The 2026 AI-Codegen Security Scanner Landscape
2026.05.02 · 8 MIN READ · A 2026 survey of security scanners for apps built by Lovable, Bolt, Cursor, Replit, and V0. How legacy SAST, modern AI-flavored scanners, …
SCANNER